Bu belge İngilizce olarak sunulmaktadır. Hukuken bağlayıcı olan İngilizce sürümdür.

Privacy Policy

Last updated: 11 October 2026

This Privacy Policy explains how Orbitex FZE LLC, a company licensed in the United Arab Emirates (trade licence no. 4431897.01) ("OrbitexGo", "we", "us") collects and uses personal data when you use the OrbitexGo website at https://orbitexgo.com and the OrbitexGo mobile apps. We are the controller of your personal data. We process it in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for customers in the European Economic Area and the United Kingdom, the GDPR and UK GDPR.

1. Data we collect

  • Account data: your email address and, if you sign in with Apple or Google, the account identifier and the name they share with us. If you use "Hide My Email" with Apple, we receive a relay address.
  • Order data: the plans you buy, prices, currency, dates, promo codes and order numbers.
  • eSIM data: the identifiers needed to deliver and support your plan, such as the ICCID, activation code and data usage reported by our network partner.
  • Payment data: Stripe processes your payment and shares with us the payment status, card brand, the last four digits of the card and the card's country. We never receive your full card number or security code.
  • Technical data: IP address, browser or device type and app version, which our servers and our network security provider process to deliver the website, prevent fraud and show prices in your local currency and language.
  • Support data: the messages you send us and our replies.
  • Preferences: the language and currency you choose.

We do not collect your location, contacts, photos or browsing activity outside our service, and we do not sell personal data or use it for third-party advertising.

2. Why we use your data (legal bases)

  • To create and deliver your order, provide your eSIM and show it in your account (performance of a contract).
  • To take payments, prevent fraud and misuse, and keep the service secure (performance of a contract and our legitimate interests).
  • To send service messages such as sign-in codes, eSIM delivery and receipts (performance of a contract).
  • To keep accounting and tax records (legal obligation).
  • To answer your questions and handle refunds (performance of a contract and legitimate interests).
  • To send marketing emails, only if you have opted in; you can unsubscribe at any time (consent).

3. Who we share data with

  • Stripe, Inc. and its affiliates, for payment processing and fraud prevention.
  • Our licensed eSIM network partners, only the information needed to issue and support your eSIM (such as the order reference and eSIM identifiers).
  • Service providers who process data on our behalf under contract: cloud hosting, network security and content delivery (Cloudflare), and transactional email delivery.
  • Apple or Google, if you choose to sign in with them.
  • Authorities, courts or advisers, when the law requires it or to protect our rights.
  • A buyer or successor, if our business is sold or reorganised, under the same protections.

4. International transfers

Our service providers may process data outside your country, including in the United States and the European Union. Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.

5. How long we keep data

  • Account data: until you delete your account.
  • Order and payment records: as long as accounting and tax laws require (at least 5 years). After account deletion they are kept without your name or email.
  • Support messages: up to 2 years after the conversation ends.
  • Server security logs: up to 30 days.

6. Cookies and similar technologies

We use only cookies and app storage that are needed for the service to work: keeping you signed in, remembering the language and currency you choose, and Stripe's fraud-prevention cookies on the payment form. We do not use advertising or tracking cookies.

7. Security

All connections are encrypted (HTTPS/TLS). Access keys and sensitive settings are stored encrypted, access to our systems is restricted and protected with two-factor authentication, and card payments are handled entirely by Stripe in line with PCI DSS.

8. Your rights

Depending on where you live, you can ask to access, correct or delete your data, receive a copy of it, restrict or object to its use, and withdraw consent at any time. You can delete your account in the app (Account → Delete account) or at https://orbitexgo.com/delete-account. For any other request, email [email protected]; we reply within 30 days. You can also complain to your local data protection authority.

9. Children

The service is intended for adults and is not directed at children under 18. We do not knowingly collect data from children.

10. Changes

We may update this policy. We will show the date of the latest version at the top and inform account holders of important changes by email.

11. Contact